North Korean Hackers Embed Malicious Code in Legitimate npm Packages
Amber | Attack Report
Download PDFThe North Korea-linked threat actor group, known as “Stressed Pungsan,” has been actively distributing malicious npm packages on the package registry. This campaign primarily targets Windows systems, achieving data exfiltration, credential theft, and lateral movement within compromised networks by infiltrating with malicious npm packages. The activities of “Stressed Pungsan” closely align with those of the MOONSTONE SLEET group.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox